Item - 2023.AU3.6

Tracking Status

  • City Council adopted this item on December 13, 14 and 15, 2023 without amendments and without debate.
  • This item was considered by Audit Committee on December 1, 2023 and was adopted with amendments. It will be considered by City Council on December 13, 14 and 15, 2023.

AU3.6 - Status Update on the City-wide Risk Governance Model

Decision Type:
ACTION
Status:
Adopted on Consent
Wards:
All

City Council Decision

City Council on December 13, 14, and 15, 2023, adopted the following:

 

1. City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2024 with an update on the implementation and maturation of Enterprise Risk Management.

 

2. City Council request the City Manager, in co-ordination with Director, Internal Audit to work with division heads to expand the inclusion of risk management considerations into reports provided to Committees and Council as applicable.

Background Information (Committee)

(November 14, 2023) Report from the Chief Technology Officer, Chief Information Security Officer, Executive Director, Toronto Emergency Management and Acting Director, Internal Audit on Status Update on the City-wide Risk Governance Model
https://www.toronto.ca/legdocs/mmis/2023/au/bgrd/backgroundfile-240773.pdf

AU3.6 - Status Update on the City-wide Risk Governance Model

Decision Type:
ACTION
Status:
Amended
Wards:
All

Committee Recommendations

The Audit Committee recommends that:

 

1. City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2024 with an update on the implementation and maturation of Enterprise Risk Management.

 

2. City Council request the City Manager, in co-ordination with Director, Internal Audit to work with division heads to expand the inclusion of risk management considerations into reports provided to Committees and Council as applicable.

Origin

(November 14, 2023) Report from the Chief Technology Officer, Chief Information Security Officer, Executive Director, Toronto Emergency Management and Acting Director, Internal Audit

Summary

This report outlines the governance model, processes, and activities that will contribute to overall Enterprise Risk Management within the City.  Enterprise Risk Management (ERM) is a structured, consistent, and continuous process that supports the achievement of the organization's objectives by identifying, assessing, responding to, and reporting on the full spectrum of risk, holistically across the organization. It also manages the combined impact of those risks as an interrelated risk portfolio.

 

The report provides an overview of the proposed City-wide Risk Governance Model.  The governance model outlines roles and responsibilities within the Enterprise Risk Management process with respect to oversight of risks throughout the organization, including risks pertaining to business continuity, cyber major incident, and technology disaster recovery.

 

While divisions across the City including Technology Services, the Office of the Chief Information Security Officer and Toronto Emergency Management have employed their own processes to manage and govern their respective risks, Enterprise Risk Management takes a holistic approach to risk management looking at risks from a City-wide perspective.

Background Information

(November 14, 2023) Report from the Chief Technology Officer, Chief Information Security Officer, Executive Director, Toronto Emergency Management and Acting Director, Internal Audit on Status Update on the City-wide Risk Governance Model
https://www.toronto.ca/legdocs/mmis/2023/au/bgrd/backgroundfile-240773.pdf

Motions

1 - Motion to Amend Item moved by Councillor Stephen Holyday (Carried)

That:

 

1.  City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2024 with an update on the implementation and maturation of Enterprise Risk Management.

 

2. City Council request the City Manager, in co-ordination with Director, Internal Audit to work with division heads to expand the inclusion of risk management considerations into reports provided to Committees and Council as applicable.


Motion to Adopt Item as Amended moved by Councillor Stephen Holyday (Carried)
Source: Toronto City Clerk at www.toronto.ca/council